Detection Method: Exif analysis

Exif analysis looks at embedded metadata in files to uncover suspicious details that could indicate malicious activity. By extracting and analyzing Exif data from images, documents, PDFs, and other attachments, this method can help spot hidden threats that would normally go undetected.
Exif analysis can detect:
  • Document timestamps that don’t match the claimed origin
  • Authorship info that conflicts with the sender’s identity
  • Signs of image or document manipulation
  • Suspicious tools used to create the file
  • Geographical data that’s inconsistent with the expected origin
For example, a phishing email claiming to be an invoice might have metadata showing it was created with unauthorized tools, edited recently, or authored by someone outside the company it’s pretending to be from.
Rule Name & Severity
Last Updated
Author
Types, Tactics & Capabilities
Attachment: PDF bid/proposal lure with credential theft indicators
3d ago
Mar 27th, 2026
Sublime Security
Attachment: PDF with a suspicious string and single URL
13d ago
Mar 17th, 2026
Sublime Security
Attachment: PDF with ReportLab library and default metadata
1mo ago
Feb 27th, 2026
Sublime Security
Attachment: Encrypted PDF with credential theft body
1mo ago
Feb 26th, 2026
Sublime Security
Attachment: Legal themed message or PDF with suspicious indicators
1mo ago
Feb 5th, 2026
Sublime Security
Attachment: Excel file with document sharing lure created by Go Excelize
1mo ago
Jan 29th, 2026
Sublime Security
Attachment: Fake lawyer & sports agent identities
2mo ago
Jan 26th, 2026
Sublime Security
Attachment: Password-protected PDF with fake document indicators
2mo ago
Jan 21st, 2026
Sublime Security
Attachment: Invoice and W-9 PDFs with suspicious creators
2mo ago
Jan 21st, 2026
Sublime Security
Attachment: Office document with VSTO add-in
2mo ago
Jan 12th, 2026
@vector_sec
Attachment: PDF file with link to fake Bitcoin exchange
2mo ago
Jan 12th, 2026
Sublime Security
Callback phishing: Social Security Administration fraud
2mo ago
Jan 12th, 2026
Sublime Security
Callback phishing: AOL senders with suspicious HTML template or PDF attachment
2mo ago
Jan 12th, 2026
Sublime Security
Attachment: Excel file with suspicious template identifier
2mo ago
Jan 12th, 2026
Sublime Security
Attachment: LNK with embedded content
2mo ago
Jan 12th, 2026
@ajpc500
Attachment: PowerPoint with suspicious hyperlink
2mo ago
Jan 12th, 2026
Sublime Security
Attachment: PDF with suspicious HeadlessChrome metadata
2mo ago
Jan 8th, 2026
Sublime Security
Attachment: PDF generated with wkhtmltopdf tool and default title
3mo ago
Dec 19th, 2025
Sublime Security
Attachment: Suspicious PDF created with headless browser
6mo ago
Sep 17th, 2025
Sublime Security
Attachment: XLSX file with suspicious print titles metadata
6mo ago
Sep 16th, 2025
Sublime Security